Your app is not everyone's app. Neither is your go-live checklist.
Answer 14 quick questions about your stack (Supabase? Stripe? AI calls? file uploads?) and get a personalized go-live checklist: only the items that apply to you, ordered by what is blocking, what is urgent, and what can wait, each with the exact dashboard path and a time estimate. Free, no signup, nothing stored on a server.
Which tool built most of your app?
14 questions, 2 minutes
Which builder made the app, whether you use Supabase, Stripe, AI APIs, file uploads, and what launch day looks like.
A checklist that is actually yours
From a bank of 40 expert items, you get only the ones your answers trigger, triaged into blocking, urgent, and can-wait.
Every item is actionable
Exact dashboard paths and commands (Supabase RLS, Stripe webhooks, spend caps), a plain-English why, and a time estimate.
Take it with you
Check items off (saved in your browser), copy as markdown, print it, or share a link that regenerates your exact list.
Prefer the one-size-fits-all version? The static 12-point security checklist is the printable subset of this generator's Supabase and secrets items.
Is this a real security audit?
No. It is a self-serve checklist built from the failure patterns we see in paid audits of AI-built apps. It tells you what to check and how; it cannot verify you did it right. For verified findings with re-runnable proofs, that is what a Ship Check is for.
Do you store my answers?
No. Your answers live in the URL fragment and your browser's localStorage. Nothing is sent to a server, which is also why the share link regenerates your exact checklist for anyone who opens it.
How is this different from the static free checklist?
The static checklist is the same 12 items for everyone. This generator asks 14 questions about your app and produces only the items that apply to you, ordered by what is blocking, what is urgent, and what can wait, with time estimates and exact dashboard paths.
My app was built with Lovable or Bolt. Do I need this?
Especially then. Builders optimize for a working demo, and the gaps they leave are consistent: RLS disabled on new tables, localhost redirect URLs, secrets in client env vars, and no rate limits. The generator asks which builder you used and adjusts for it.
Which stacks does it cover?
Supabase (RLS, auth, storage, backups, SMTP), Stripe and other payment providers, LLM API usage (spend caps, key hygiene, prompt injection), Vercel-style hosting, DNS and email deliverability, monitoring, and the legal basics. If you answer no to a stack, its items simply do not appear.
How long does the checklist take to finish?
A typical list is 15 to 30 items. The blocking tier is usually an afternoon of focused work; the full list, including urgent items, tends to land between one and two days. Each item carries its own time estimate so you can plan it.